Impact
An authenticated user can manipulate sorting parameters that are not properly escaped, enabling the execution of arbitrary SQL statements within the database. The flaw can lead to unauthorized data disclosure, modification, or deletion, compromising confidentiality, integrity, and availability of stored information. The weakness is a classic SQL injection (CWE‑89).
Affected Systems
The vulnerability affects all PHP Jabbers application scripts listed, including Appointment Scheduler, Auto Classifieds Script, Availability Booking Calendar, Bus Reservation System, Business Directory Script, Car Park Booking System, Car Rental Script, Cinema Booking System, Cleaning Business Software, Equipment Rental Script, Event Booking Calendar, Event Ticketing System, Food Delivery Script, Hotel Booking System, Job Listing Script, Limo Booking Software, Meeting Room Booking System, Member Directory Script, Member Login Script, PHP Event Calendar, PHP Newsletter Script, PHP Shopping Cart, Product Comparison Script, Property Listing Script, Rental Property Booking Calendar, Restaurant Booking System, Service Booking Script, Shuttle Booking Software, Taxi Booking Script, Ticket Support Script, Time Slots Booking Calendar, Travel Tours Script, Vacation Rental Script, and Yacht Listing Script. The affected product versions are not specified; the issue is reported to exist across the current releases until a fixed version is released by the vendor.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog, which reduces the likelihood of known exploitation but it remains a critical flaw if an attacker gains authenticated access. Because the flaw requires an authenticated session, the attack vector is inferred to be an authorized user or compromise of credentials. If an attacker can log in, they can execute arbitrary SQL, leading to potential data exfiltration or manipulation. Prompt patching is therefore essential to mitigate the risk of a substantial data breach.
OpenCVE Enrichment